Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents
Persistent AI agents extend large language models (LLMs) beyond single-turn interaction into long-lived software systems. Unlike traditional chat assistants, unsafe content in these agents can propagate through persistent state, reusable skills, and tool-mediated interactions, creating a substantially larger semantic attack surface. We observe that most security-critical interactions in such agents are transmitted through natural-language token flows, including memory updates, tool arguments, retrieved files, and inter-component communications. This observation enables a new security formulati
Lineage graph
Paper → model → repo connections mined from source citations (Tier-1 exact match).
Why these links exist
Every edge carries a method, confidence, and the source snippet that justified it — so bad links are debuggable.
- PossiblePossibly related (embedding) · 57%Prompt injection is exploiting enterprise AI's biggest design flaws by targeting agents, RAG pipelines and model routers →
- PossiblePossibly related (embedding) · 57%node9-ai/node9-proxy →
- PossiblePossibly related (embedding) · 56%opensandbox-group/OpenSandbox →
- PossiblePossibly related (embedding) · 55%killertcell428/aigis →
- PossiblePossibly related (embedding) · 55%TalEliyahu/Awesome-AI-Security →
- LinkedLinked via arxiv author · 85%Puji Wang →
“Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents”
- LinkedLinked via arxiv author · 85%Yingchen Zhang →
“Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents”
- LinkedLinked via arxiv author · 85%Ruqing Zhang →
“Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents”
